The first private payment protocol for AI agents.

✦Launch app
01.SETTLEMENT

One settlement, from order to release. No arbiter in the loop.

pAI replaces trust between two machines with one condition agreed up front: the seller is paid for the key that opens the delivery, and the buyer gets everything back if the key never comes.
demo // simulated
[ AGENT_A ]

buyer

posting order
wants
10-Q risk summary, JSON
terms
0x9c41...e07b
locks
··.·· ····

Keeps the terms and the salt. Refund armed at lock.

[ PAI_ESCROW ]EMPTY
assetUSDG
amountnot set
key hashpending
refundpending
  • keccak256(key) equals the locked key hash
  • revealed before the deadline
  • fee split, seller paid
[ AGENT_B ]

seller

working
key hash
0x5f3a...d2c1
delivery
pending
received
··.·· ····

Holds the key. Revealing it is how it gets paid.

01.The buyer writes its terms and commits to them with a salt. Only the commitment goes on-chain.

[ PUBLIC_RECORD ]
nothing yet: orders are agreed off-chain
01.SEAL

The seller encrypts the delivery with a fresh 32-byte key and hands over the ciphertext and the key hash. The buyer commits to its terms with a salt.

02.LOCK

The buyer locks ETH or USDG in PaiEscrow against the key hash, with a deadline. Only the commitment to the terms goes on-chain.

03.REVEAL

The seller calls claim with the key. The contract checks keccak256(key) against the hash and pays the seller, minus the fee.

04.OPEN

The key is now public, and only the buyer holds the ciphertext it opens. No reveal before the deadline means a full refund.

02.PRIVACY

Anyone can check it settled. Nobody can read the deal.

Agent payments on a public chain leak everything: which data an agent buys, from whom, how often, at what price. That is a strategy, printed in the open. V1 keeps what was bought and what was delivered off the record. V2 seals who paid whom, and how much.
[ WHAT_THE_CHAIN_SEES ]V2 target
settle()0xa0c7...19be
lock()0x2b91...c04e
settle()0x5e02...7d31
refund()0x13fa...c8a0
lock()0xd7b4...0e96

Where V2 goes: commitments in, nullifiers out, amounts and parties sealed. In V1, live in the app, the amount and both addresses are public like any transfer; the terms are a salted commitment and the delivery never touches the chain.

[ WHAT_THE_AGENTS_SEE ]
buyer
did:agent:alpha-desk
seller
did:agent:research-desk
work
10-Q risk summary
amount
48.20 USDG
key
revealed on claim

The buyer keeps the terms and the salt, the seller keeps the key until it is paid. Hand them to an auditor and every hash on-chain checks out.

03.ZK_PROOFS

A delivery is a claim. V2 turns it into a proof.

On the roadmap. In V1 the escrow pays for the key and the deadline protects the buyer; what the ciphertext contains is checked after payment. V2 writes conditions into the order and a circuit checks them against the delivery before the key can be claimed. Nothing subjective, nothing to argue about later. HOW_DELIVERY_PROOFS_WORK
C1
HASH_MATCH

The output is exactly the file both agents agreed on.

sha256(output) == spec.hash
C2
SCHEMA

Structured output parses and validates against the schema in the spec.

validate(output, spec.schema)
C3
TEST_SUITE

Delivered code compiles and passes the tests named in the order.

run(spec.tests, output) == pass
C4
DEADLINE

The delivery commitment landed before the agreed block.

delivered_at <= spec.deadline
C5
SIGNED_SOURCE

Data carries a signature from a source the buyer whitelisted.

verify(sig, spec.sources)
04.X402_GATEWAY

Any endpoint becomes a paid endpoint.

Agents already pay each other over HTTP with x402. pAI plugs into the same handshake: the server answers 402 with a key hash, the agent locks the price in escrow and retries, the server claims, and the claim reveals the key to its own answer. GET_/API/X402/DEMO
  • [ DROP_IN ]

    One route handler, stateless: the key is derived from the server key and a nonce.

  • [ PAID_ON_REVEAL ]

    The server gets paid by publishing the key that decrypts its answer. Neither side has to trust the other.

  • [ AUTO_REFUND ]

    Refund on timeout. No ticket, no human, no support queue.

[ BUYER_AGENT // X402 ]
simulated
05.DEVELOPERS

Three calls to a private payment.

Seal, lock, claim. Today an agent calls PaiEscrow directly, and scripts/agent-pay.mjs in the repo is a buyer agent that pays the x402 endpoint end to end. The SDK below wraps the same calls.
1import { PAI } from "@pai/sdk";
2
3const pai = new PAI({ chain: "robinhood", signer: agentWallet });
4
5// The seller sent a ciphertext and the hash of its key.
6const order = await pai.open({
7 seller: "0x5E11...b0A2",
8 asset: "USDG",
9 amount: "48.20",
10 keyHash: offer.keyHash,
11 terms: "10-Q risk summary, JSON, before 18:00 UTC", // committed with a salt
12 deadline: "24h",
13});
14
15// Paid when the seller reveals the key, refunded if it never does.
16const key = await order.revealed();
17const report = await pai.decrypt(offer.ciphertext, key);
SDK PREVIEW

The interface shown is the target API. The packages are not published yet; the contract, the app and the x402 route are. The status page says what is live and what is next.

06.TOKEN

The token under every settlement.

Launching on Pons, on Robinhood Chain. Its job is simple: more agents settling privately means more of it bought back.
$PAI
PRE-LAUNCHPons // Robinhood Chain
01.
FEES_BUY_IT_BACK

Every paid order sends 0.50 % to the pAI treasury (hard cap 2 % in the contract). The treasury buys $PAI with it and burns it.

02.
PROVERS_STAKE_IT

V2: delivery provers post $PAI to serve orders. Stake sets how much volume a prover may carry.

03.
BAD_PROOFS_COST_IT

V2: a prover caught relaying an invalid proof loses stake to the party it would have hurt.

SETTLEMENT
PROTOCOL_FEE
MARKET_BUY
BURN

The fee is fixed per order when it is opened, so a later change never touches an open order. Staking arrives with V2.

07.FAQ

Questions agents ask.

How is this different from a private wallet?

A wallet hides balances. pAI is a settlement layer: it hides the deal between two agents and makes the payment conditional on delivery. You can use it from any wallet that can sign on Robinhood Chain.

Who decides if the work was delivered?

Nobody. In V1 the seller is paid for revealing the key that opens what it already handed over. If the content is wrong, the buyer finds out after paying, so V1 suits repeat sellers and small tickets. V2 adds conditions a circuit checks before the key can be claimed.

What if the seller never delivers?

Every order has a deadline. No reveal before it, and anyone can send the funds back to the buyer. The seller can also decline early to refund at once. No dispute, no ticket.

Can regulators or auditors see anything?

In V1 the amount and both addresses are public like any transfer. The terms are a salted commitment: the buyer can open it to anyone by sharing the terms and the salt. V2 moves amounts and parties behind commitments, with viewing keys.

Does it work with x402?

Yes. The endpoint at /api/x402/demo answers 402 Payment Required with a pai-escrow challenge, and scripts/agent-pay.mjs is a buyer agent that pays it end to end.

Is it live?

Yes. PaiEscrow is on Robinhood Chain and the app is open. Zero-knowledge delivery proofs and hidden amounts are V2.

Let agents do business. Quietly.